Assistant Manager, Technology Centre

AIA Hong Kong and Macau

Kuala Lumpur

On-site

MYR 180,000 - 300,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AIA Hong Kong and Macau is seeking a Security & Cloud Architect in Kuala Lumpur to lead security-focused design of cloud solutions across applications, data, and infrastructure with an Azure emphasis.

You will assess GenAI/LLM security risks, drive secure-by-design practices, and guide DevSecOps integration while partnering with architecture, engineering and delivery teams to ensure regulatory compliance.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Software/Computer Engineering, Enterprise/Solution Architecture, or related discipline.
  • 8+ years in solution and/or security architecture roles (10–15 years preferred for senior profiles).
  • 5+ years hands-on experience in cloud and application security architecture (IaaS / PaaS / SaaS).
  • Experience delivering secure digital solutions within financial services or insurance environments (preferred).
  • Exposure to API-based architectures, microservices, event-driven integration, and DevSecOps practices.

Responsibilities

  • Lead security-focused design of cloud solutions across application, integration, data, and infrastructure layers (Azure-centric).
  • Shape and evolve reference architectures and secure design patterns with enterprise standards.
  • Produce and maintain architecture deliverables (e.g. SAD, HLD) with security considerations.
  • Review authentication and authorization models for cloud apps, ensuring strong access control and data protection.
  • Embed secure-by-design principles across APIs, integrations, and middleware components.
  • Provide security input for GenAI/LLMs and address GenAI-specific risks.
  • Automate security checks across delivery pipelines and monitor evolving threats.
  • Support Architecture Review Board discussions and ensure compliance with policies and standards.
  • Mentor junior team members and promote secure design awareness.
  • Communicate risks and trade-offs to leadership and stakeholders.

Skills

Security architecture
Cloud security
GenAI security
Identity and access management
Data protection
Cryptography
Compliance awareness
Communication
DevSecOps
Threat modelling

Education

Bachelor’s degree in CS/Info Security/Engineering

Tools

Azure

Job description

Are you ready to shape a better tomorrow? AIA Digital+ is a Technology, Digital and Analytics innovation hub dedicated to powering AIA to be more efficient, connected and innovative as it fulfils its Purpose to help millions of people across Asia-Pacific live Healthier, Longer, Better Lives. If you are hungry and driven to play an active role in shaping a better tomorrow, we want to hear from you. Because the work we do at AIA Digital+ makes a difference in the lives of millions of people, every day. We will equip you with the critical skills, tools and technology, and endless opportunities to learn, contribute and thrive in a dynamic and exciting environment. If you want to shape a brighter future at AIA Digital+, please read on.

About the Role

We are seeking a Security & Cloud Architect with strong hands‑on experience in designing and reviewing secure, cloud‑native solutions across interconnected applications, platforms, and infrastructure. The role provides security architecture leadership and advisory support covering application security, identity and access management, data protection, cryptographic controls, compliance, and the secure adoption of emerging technologies such as Generative AI (GenAI) and Large Language Models (LLMs). This position partners closely with architecture, engineering, and delivery teams to perform security design reviews, architecture assessments, and risk‑based advisory for strategic digital initiatives—ensuring solutions enable business growth while maintaining a strong security and regulatory posture.

Key Responsibilities
  • Secure Solution Design & Technical Direction Lead security‑focused design of cloud solutions across application, integration, data, and infrastructure layers (Azure‑centric). Shape and evolve reference architectures and secure design patterns aligned to enterprise and Group standards. Produce and maintain key architecture deliverables (e.g. SAD, HLD) with clear security considerations and design decisions.
  • Cloud Application Security & Identity Design and review authentication and authorization models for cloud applications, ensuring strong access control, token handling, session management, cryptography, and data protection. Assess security implications of new or changed applications, tools, and platforms, including impact to existing architectures. Embed secure‑by‑design principles across APIs, integrations, and middleware components.
  • Emerging Technology & GenAI Security Provide security architecture input and assessment for solutions leveraging GenAI, LLMs, and machine‑learning technologies. Identify and address GenAI‑specific risks such as prompt injection, insecure outputs, model abuse, data poisoning, and sensitive data exposure. Apply OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks when conducting design reviews and security assessments. Establish guardrails for LLM usage, including validation, access restriction, monitoring, data boundaries, and human‑oversight controls. Support responsible and compliant GenAI adoption aligned with enterprise risk, privacy, and regulatory expectations.
  • Security Architecture Execution & Improvement Implement and continuously enhance cloud security architecture and controls. Drive automation of security checks and controls across delivery pipelines and operational processes. Monitor evolving threats, vulnerabilities, and industry practices to improve the organisation’s security posture.
  • Risk, Compliance & Architecture Assurance Perform threat modelling, risk assessments, and security impact analysis for new and existing solutions. Contribute to Architecture Review Board (ARB) discussions and provide architectural assurance against standards, policies, and roadmaps. Ensure compliance with internal IT policies, regulatory requirements, and industry standards (e.g. NIST, PCI DSS). Support Local Information Security (LIS) activities related to audits, compliance reviews, and control validation.
  • Delivery Partnership & Advisory Work closely with enterprise architects, developers, DevOps teams, and vendors throughout delivery lifecycles. Provide practical guidance to resolve security design and implementation challenges. Communicate security risks and trade‑offs clearly to technical and business stakeholders, including senior leadership.
  • Capability Building & Enablement Act as the security architecture subject matter expert across cloud, application, and GenAI‑enabled solutions. Mentor junior team members and promote secure design awareness across IT and business teams. Facilitate balanced discussions where business needs, innovation, and security standards intersect.
Minimum Requirements

Education Bachelor’s degree in Computer Science, Information Security, Software/Computer Engineering, Enterprise/Solution Architecture, or related discipline.

Experience 8+ years in solution and/or security architecture roles (10–15 years preferred for senior profiles). 5+ years hands‑on experience in cloud and application security architecture (IaaS / PaaS / SaaS). Experience delivering secure digital solutions within financial services or insurance environments (preferred). Exposure to API‑based architectures, microservices, event‑driven integration, and DevSecOps practices.

Security & Technology Expertise Strong understanding of security frameworks such as ISO/IEC 27001, NIST, and COBIT; familiarity with PDPA, GDPR, and PCI DSS where applicable. Deep knowledge of identity and access management, data protection, cryptographic controls, and cloud security (Azure preferred). Working knowledge of CI/CD pipelines, infrastructure‑as‑code, and operational security guardrails. Awareness or hands‑on experience securing GenAI / LLM‑enabled applications, including prompt safety and data governance. Familiarity with OWASP Top 10 for LLM Applications and/or OWASP Top 10 for Machine Learning Security Risks.

Professional Attributes Strong communication skills with the ability to translate complex security topics into business‑relevant language. Analytical, pragmatic, and decisive with a collaborative mindset and strong ownership.

Certifications (Preferred) Security / Cloud: CISSP, CCSP, CISM, SABSA, Azure Solutions Architect, Azure DevOps. Architecture / Governance (nice to have): TOGAF, IASA. GenAI / AI security‑related training or experience (must).

Build a career with us as we help our customers and the community live healthier, longer, better lives.

You are responsible for ensuring that the information you submit is accurate and up-to-date.

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. It's about finding new ways to not only better people's lives, but to better the communities and environments we live in. As the largest listed company on the Hong Kong Stock Exchange, we’ve been proudly making a difference for people and communities across Asia for over a century. And we build on this every day with our ambition to engage one billion people to live Healthier, Longer, Better Lives by 2030. If you work at AIA, you play an important part in this movement. Which is why we give you every opportunity to learn, grow and shape your career - your way. Inspiring and supporting you to thrive - not just at work, but in life. Believe in better with AIA.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager, Enterprise Platform Transformation
Assistant Manager, Enterprise Platform Transformation

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA Hong Kong and Macau • Malaysia

On-site
MYR 120,000 - 180,000
Associate Director,Information Security Strategy
Associate Director,Information Security Strategy

aia • Cyberjaya

On-site
MYR 180,000 - 300,000
Analyst, Transformation Automation
Analyst, Transformation Automation

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Intern, Cyber Security
Intern, Cyber Security

AIA Hong Kong and Macau • Cyberjaya

On-site
MYR 17,000 - 29,000
Intern, Cyber Security
Intern, Cyber Security

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 13,000 - 20,000
Associate Director,Information Security Strategy
Associate Director,Information Security Strategy

AIA Hong Kong and Macau • Malaysia

On-site
MYR 100,000 - 150,000
Manager, Service Delivery Partner
Manager, Service Delivery Partner

AIA Hong Kong and Macau • Kuala Lumpur

On-site
MYR 90,000 - 150,000
Lead Analyst, Operations
Lead Analyst, Operations

AIA Hong Kong and Macau • Kuala Lumpur

On-site
Lead Analyst, Identity & Access Management
Lead Analyst, Identity & Access Management

AIA Hong Kong and Macau • Cyberjaya

On-site
MYR 120,000 - 180,000